Ransom

Ransom:Win32/Genasom.IN malicious file

Malware Removal

The Ransom:Win32/Genasom.IN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Genasom.IN virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Ransom:Win32/Genasom.IN?


File Info:

name: B8D1160966BF7471E2C2.mlw
path: /opt/CAPEv2/storage/binaries/00e7d17872f55958c860f87c5bcc44f7947735a5f516f93f9fb611cd3b66cced
crc32: 4F9AB7A3
md5: b8d1160966bf7471e2c2f068385fbfe2
sha1: 6a0777d19144f0af3e96f8026bac469435a55547
sha256: 00e7d17872f55958c860f87c5bcc44f7947735a5f516f93f9fb611cd3b66cced
sha512: fd9a46318e3e45f0846dfe357db3a06a62c42b78b38e1d776025b5e69384bfcdc0b4c730b7d7a5cf9225cb9acd483091781f93031b628a4fdeaf7d3a2eebae98
ssdeep: 768:qs6Jr2rTi31prirL1CiZkCzc9cHKjEtiko8FXAIAOW1yP9aQtbu:tF/iFprq1CwkCVHltw+wIAt1yP9aQM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A8536B5A3853C0B3E4064575868686C11FBF6D133AEB542FFF94114E9EF128849BAAF2
sha3_384: b92c71a637b9e9bc2bdc79cc7255e316818fa73eab8aff474b1fede5911e0020ddda576eb7ac2dd6f9de80fdf6fd7e42
ep_bytes: e85a170000e916feffff558bec81ec28
timestamp: 2012-06-12 02:48:15

Version Info:

0: [No Data]

Ransom:Win32/Genasom.IN also known as:

LionicTrojan.Win32.Generic.lyNC
DrWebTrojan.Winlock.6027
MicroWorld-eScanGen:Variant.Zusy.9040
FireEyeGeneric.mg.b8d1160966bf7471
CAT-QuickHealTrojan.Vundo.Gen
McAfeeArtemis!B8D1160966BF
CylanceUnsafe
ZillyaTrojan.Gimemo.Win32.2503
SangforTrojan.Win32.Zusy.frzc
K7AntiVirusSpyware ( 002edad51 )
AlibabaRansom:Win32/Genasom.e94e0416
K7GWSpyware ( 002edad51 )
Cybereasonmalicious.966bf7
BitDefenderThetaGen:NN.ZexaF.34582.dqY@ayIghKhk
VirITTrojan.Win32.Generic.BPZF
CyrenW32/Zbot.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/SpyVoltar.A
TrendMicro-HouseCallTROJ_SPNR.30BI13
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-624885
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.9040
NANO-AntivirusTrojan.Win32.Gimemo.sthul
AvastWin32:Buterat-MR [Trj]
TencentMalware.Win32.Gencirc.10c3a438
Ad-AwareGen:Variant.Zusy.9040
EmsisoftGen:Variant.Zusy.9040 (B)
ComodoMalware@#1ueiagajliiv9
VIPREGen:Variant.Zusy.9040
TrendMicroTROJ_SPNR.30AE13
McAfee-GW-EditionBehavesLike.Win32.Generic.kh
SophosMal/Generic-S
IkarusBackdoor.Win32.Buterat
GDataGen:Variant.Zusy.9040
JiangminTrojan/Gimemo.ckn
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen7
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.294
ViRobotTrojan.Win32.A.Gimemo.62980
MicrosoftRansom:Win32/Genasom.IN
CynetMalicious (score: 99)
ALYacGen:Variant.Zusy.9040
MalwarebytesMalware.AI.3797926622
APEXMalicious
RisingTrojan.Generic@AI.83 (RDML:hVd6PFMpojbEHFCUDnsVZA)
YandexTrojan.GenAsa!qzB1zZc+55c
MaxSecureTrojan.Malware.4328208.susgen
FortinetW32/SpyVoltar.A!tr
AVGWin32:Buterat-MR [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ransom:Win32/Genasom.IN?

Ransom:Win32/Genasom.IN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment